KACE Systems Management Appliance (SMA)
Please tell us how you’d like to see the KACE Systems Management Appliance product improved!
356 results found
-
Automate changing local admin passwords on large Organizations
We are required by Policy to change local admin passwords quarterly and upon staff departure. This results in over 600 manual password changes.
Does Quest have a way to automate this, or could a Tool/KBin be created so we can input a password and apply it to our servers?
d
7 votescompleted ·AdminKent Feid (Director of Product Management | Data Protection & KACE Unified Endpoint Management, Quest KACE) responded
We are excited to announce that as part of the KACE SMA 12.0 release, we have made multiple user management and credential enhancements. As part of these enhancements, we have added the ability to disable/delete the local built-in admin account, which takes away the need to change the password on a reoccurring basis to meet your companies password security policy. This enhancement applies to both Org and Non-Org appliances. This approach, therefore, provides you the flexibility of using either LDAP or SAML to manage all user credentials taking on the password complexity and change cadence defined by your preferred methodology. Additionally, for customers leveraging Org's, we have added the ability to use LDAP/SAML as a means of authenticating at the system level with the option of making a specific role a global admin. If enabled, it automatically allows a user in that group to gain admin access to…
-
Speed up offboard backup SFTP transfers
KACE support has confirmed the SMA is limited to a transfer rate of approx 10-11 MB/s when offboarding backups via SFTP. This needs to be fixed so we can transfer at appropriate, faster speeds (much closer to 1000mbps on a gigabit LAN connection). See support ticket 4688470 for details.
17 votesThis was completed
-
Patching Status Dashboard Single Pane of Glass
Please create a patch management dashboard that would allow us to quickly view the patching status of all the machines. Such as so many machines are 100% patched. These machines have errors with patching. Compliance per patch. Patches detected but not downloaded. Machines pending reboot. Even a section for just for logged errors throughout the entire patching process. When we see machines with errors let us select them and try to force the patches at that time. I think we need more single panes of glass throughout the Kace appliance but patching is most crucial.
12 votesCompleted in SMA 11.0
-
Enable patching for Windows Server 2019
Windows Server 2019 has been release for almost a year go a. So it's about the time for KACE to start supporting patching for it.
12 votes -
sign-on -- Azure Active Directory & Others via OAUTH
The 2FA with Google is a great first step, but we would like to see this 2FA/Single Sign-on pushed a step further. We would like the ability to push OAuth's to other avenues. I personally would like to see an integration in to Azure AD, but with a standardized OAuth should be able to connect to others.
22 votesResolved with SAML integration
-
Service Desk: Show attached emails and embedded images
Current issue/state:
When tickets are created via email and contain an attached mail this attachment is not shown - not even as downloadable attachment.
Same behavior is when Images are embedded into an html mail sent to Service Desk.
Desired functionality:
Please allow at least a file download of the eml/mime file so the content a ticket creator is referring to isn't going to get lost.
56 votesThis was completed as per the request.
-
Service Desk API
I need to be able to create, update, and close tickets from external sources (other billing systems, etc). There appear to be APIs for most modules but none for Service Desk. Email is not sufficient for ticket operations.
52 votesThis was completed in SMA 9.0
https://support.quest.com/download/downloads?id=6089103 -
Create Knowledge base articles from Tickets.
Create Knowledge base articles from Tickets.
A lot of dedicated SD tools allow KB creation for tickets, or searching tickets from the KB.3 votesFrom ticket detail, choose “Create knowledge base article”
-
KACE Variable for OS-Native HKLM:Software and C:\Windows\system32
As you may know the KACE K1000 agent is a 32-Bit process.
As the process is 32-bit it does not have native access to c:\Windows\system32, c:\program Files or HKLM\Software on 64-Bit systems, requiring that scripts are forked with conditions for the redirected paths. This adds a lot of unnecessary steps and complications to KACE Scripts, especially ones with multiple steps.
The agent currently has several built-in variables such as
$(KACEDEPENDENCYDIRWould it be possible for Quest to implement 2 new variables to their agent for 64-Bit systems.
$KACE_SYSTEM32 (Redirects to C:\Windows\sysnative) on 64-Bit machines) 32-Bit machines would direct…
25 votesCompleted in 10.0
-
Support Windows 10 Feature Update installations via KACE patching.
With the new model of Windows updates, we need to be able to easily push these feature updates such as Anniversary Edition via the KACE in order for it to fully replace the current functionality of a WSUS server.
524 votesCompleted in SMA 10.2 which was generally available on May 11, 2020
-
Remove space in French version of ticket number [TICKET :0000]
In the French version (9.0.270): there is a space in ticket number (which is unexpected for a id.
[TICKET:0000] would be far more logical than [TICKET :0000].(incidentally, in a sentence, French would put a space before and after the colon
3 votesCompleted in SMA 9.1
-
Add Zoom to the Patch Catalog
I see that GoToMeeting is in the patch catalog. Can Zoom be added as well?
28 votesZoom for Mac was added on 4/14/2020
-
Active Directory Federation Services (ADFS)
Our security team suggested us to use ADFS. ADFS could allow us to sync multiple domain and/or forests. Would QUEST consider adding this feature?
8 votes -
Location Overview
When I open a "location", only the inventory is displayed - no assets. For example, we have assigned a monitor asset to a location - but this monitor is not displayed. It should appear in the "location" everything assigned - otherwise you do not need a location.
390 votesCompleted in SMA 9.1
-
Remove Powershell from new Kace Agent version 7.0.763
It's giving our environment all kinds of issues. Inventory will not update on some agents, getting cabarc.exe errors randomly, on all our servers we were getting runkbox.exe errors causing kbox agent to crash. Had to downgrade back to version 6.4.522 to get things stable again.
63 votes -
Allow users to download on any computer regardless of assignment (v7.0.121306)
In versions 6.4 and older users were able to download software from the User Portal on any computer. In version 7.0 KACE now only allows users to download software to computers that are assigned to them.
This is extremely inconvenient for shared computers. In conference rooms, users aren't able to download software for trainings until the computer checks-in, which for our environment is 2 hours, and by then the meeting is done. This also affects computers used by multiple users in shifts. If our devs put out a new version of software between shifts, the second shift users aren't able…
103 votesThis issue was confirmed as fixed in version 7.1.
Thank you for bringing this to our attention and your patience in awaiting a response.
We are trying to work through the suggestions, and are starting to reach out to review findings before updating status. You are correct, this should have been changed to complete with the 7.1 release. -
List Windows 10 OS as a single OS instead of separating by build number
Currently, every new "version" of Windows 10, by whatever identifier KACE is using, shows up as a "different operating system" for purposes of determining which OS to install software on. E.g. the Software Detail for Foocorp Widget lists "Supported Operating Systems" of Win7, Win7 x64, Win8, etc. - and then three separate instances of "Windows 10 Enterprise x64" differentiated by build number, according to KACE Support.
The effect is that with every new build of Win10, all of our software installs break as it's a "new OS" not listed as supported in the software record. Not to mention that pretty…
28 votes -
Free SSL certificates from Let's Encrypt
Add the ability to get a free SSL certificates from Let's Encrypt (www.letsencrypt.org) and have it auto-renew with their client.
You are able to use their certificates without the client but they expire after 90 days making them hard to manage in the long term.
108 votesThis feature was added in v13.0. Review release notes and downloads here:
-
reverse proxy
Supporting a reverse proxy setup or providing guidance on how to set up a reverse proxy for the K1000 would be very beneficial for added security. The setup would be something like this:
K1000 appliance on the internal network behind a firewall
A reverse proxy on the DMZ (e.g. IIS 8 with ARR)Currently trying to set this up is a huge headache and I'm running into all sorts of issues and problems. It would be better from a security standpoint if the K1000 sat behind a reverse proxy.
A specific use case would be when an organization has an…
16 votesIf this does not address the root request and reverse proxy per se is required, please create another UserVoice request.
The new agent security features in 11.0 are designed to support agents connecting to an SMA inside the firewall from outside the firewall. This can be accomplished either by port forwarding at the firewall or by configuring a Reverse Proxy in the DMZ to forward https traffic on port 443 with the Server Name Indication set to “konea” to the SMA. This will allow external agents to connect to the SMA while blocking web browsers from accessing the SMA externally.
-
Ability to schedule Import Assets
Can K1000 have an ability to scheduled Import Assets?
3 votesCompleted in 10.0
- Don't see your idea?